US2009106548A1PendingUtilityA1

Method for controlling secured transactions using a single physical device, corresponding physical device, system and computer program

Assignee: FRANCE TELECOMPriority: Jul 26, 2005Filed: Jul 18, 2006Published: Apr 23, 2009
Est. expiryJul 26, 2025(expired)· nominal 20-yr term from priority
H04L 2209/56H04L 9/3263
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method is provided for controlling secure transactions using a physical device held by a user and bearing at least one pair of asymmetric keys, including a device public key and a corresponding device private key. The method includes, prior to implementing the physical device, certifying the device public key with a first certification key of a particular certifying authority, delivering a device certificate after verifying that the device private key is housed in a tamper-proof zone of the physical device; verifying the device certificate by a second certification key corresponding to the first certification key; and in case of a positive verification, registering the user with a provider delivering a provider certificate corresponding to the signature by the provider of the device public key and an identifier of the user.

Claims

exact text as granted — not AI-modified
1 . Method for the control of secured transactions implementing a physical device held by a user and bearing at least one pair of asymmetric keys, comprising a device public key and a corresponding device private key, wherein the method comprises the following steps:
 prior to commissioning said physical device, a first step of certifying said device public key by signing with a first certification key of a particular certification authority, issuing a device certificate, after verification that said device private key is housed in a tamper-proof zone of said physical device;   a step of verification of said device certificate by a second certification key corresponding to said first certification key;   in the event of positive verification, a step of registering said user with a provider issuing a provider certificate corresponding to a signing by said provider of said device public key and of an identifier of this user.   
   
   
       2 . Control method according to  claim 1 , wherein said particular certification authority is a manufacturer of said physical device. 
   
   
       3 . Control method according to  claim 1 , wherein said device certificate is stored in a freely read-accessible memory zone of said physical device. 
   
   
       4 . Control method according to  claim 1  said device certificate also signs at least one piece of information representing said physical device. 
   
   
       5 . Control method according to  claim 4 , wherein said piece of information representing said physical device belongs to the group comprising the following pieces of information:
 type of physical device;
 identification of the manufacturer of said physical device; 
 type of cryptographic algorithm used by said physical device; 
 serial number of said physical device. 
   
   
   
       6 . Control method according to  claim 1 , wherein said verification step is performed by said provider. 
   
   
       7 . Control method according to  claim 1 , wherein said first certification key is a private key and said second certification key is a public key. 
   
   
       8 . Control method according to  claim 1 , wherein said particular certification authority uses a symmetrical key, so that said first certification key and said second certification key are identical. 
   
   
       9 . Control method according to  claim 8 , wherein said step of certification is implemented on the basis of said symmetrical key by said particular certification authority upon a request by a manufacturer of said device, and said verification step is implemented by said particular certification authority upon a request by said provider. 
   
   
       10 . Physical device held by a user and designed to be used during secured transactions, said physical device bearing at least one first pair of asymmetric keys comprising a device public key and a corresponding device private key wherein the physical device is also associated to a device certificate, issued after it has been verified that said device private key is housed in a tamper-proof zone of said physical device and corresponding to a signing of said first device public key by a first certification key of a particular certification authority, and wherein said device certificate is stored in said physical device prior to its commissioning or provided to the user of said physical device on an external carrier. 
   
   
       11 . Computer program product stored on a carrier that is computer-readable and/or executable by a microprocessor, wherein the product comprises program code instructions to implement at least one step of a method for controlling secured transactions implementing a physical device held by a user and bearing at least one pair of asymmetric keys, comprising a device public key and a corresponding device private key, wherein the method comprises:
 prior to commissioning said physical device, a first step of certifying said device public key by signing with a first certification key of a particular certification authority, issuing a device certificate, after verification that said device private key is housed in a tamper-proof zone of said physical device;   a step of verification of said device certificate by a second certification key corresponding to said first certification key; and   in the event of positive verification, a step of registering said user with a provider issuing a provider certificate corresponding to a signing by said provider of said device public key and of an identifier of this user.   
   
   
       12 . System for the controlling of secured transactions in a communications network, implementing a physical device held by a user and bearing at least one pair of asymmetric keys, comprising a device public key and a corresponding device private key, wherein the system comprises at least:
 a particular certification server connected to said network, issuing to said physical device, after verification that said device private key is housed in a tamper-proof zone of said physical device and prior to its commissioning, a device certificate corresponding to a signing of said device public key by a first certification key of said particular certification server;   a server, which verifies said device certificate by a second certification key corresponding to said first certification key, said verification server being connected to said network; and   a server, which registers said user with a provider, issuing to said user, in the event of positive verification by said verification server, a provider certificate corresponding to a signing by said provider of said device public key and of an identifier of said user, said registering server being connected to said network.

Join the waitlist — get patent alerts

Track US2009106548A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.